Documentation
¶
Overview ¶
Package openfile opens files that a build may have placed in a snapshot.
A snapshot is attacker-controlled: an ExecOp can mknod a device node or mkfifo with the default capability set. Opening such an inode from the daemon resolves it against the host, so the daemon would act on a device the sandbox itself is denied, or block indefinitely in open(2) on a fifo with no writer. It refuses anything that is not a regular file.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ErrNotRegular = errors.New("not a regular file")
ErrNotRegular is reported when the path exists but is not a regular file.
Functions ¶
func Regular ¶
Regular opens p for reading and fails unless p is a regular file. Callers are expected to have resolved p within the snapshot already, for example with containerd/continuity fs.RootPath.
func RegularInRoot ¶
RegularInRoot opens name inside root for reading and fails unless it is a regular file. Unlike Regular it resolves name itself, confined to root, and does so as a single operation: a process running against the same mount cannot swap a path component between the resolution and the open. Use it when the mount may be mutated while it is read, as a gateway container mount can be.
Types ¶
This section is empty.